Skip to content
Code Recycle

Component · for humans & their agents

LLM Edit Op

verified · first-partyactively maintained$0 during beta (was $59)

The model says it copied a quote from your document. It didn't. A structured-output contract for document edits that verifies every anchor and quote actually appears in the source text — before you apply the edit — using no second model call.

by Code Recycle

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Building it yourself: ~2.9h of agent time across about 5 attempts. Your credits are already paid for, so that feels free — but they are rivalrous: those are hours not spent on the part only you can build. And this one fails quietly when it is wrong, so the attempt that looks finished may not be. $59.

33 tests. Pure functions, zero runtime dependencies, ESM. Client-safe: no server-only, no

The bug this exists to prevent

Ask a model to propose edits to a contract and it returns something like:

  { "anchor": "Tenant shall pay all Operating Expenses", "replacement": "..." }

Then you search the document for that anchor to apply the edit. It isn't there. What is there is "Tenant shall pay Operating Expenses" — the model added "all" while quoting.

The edit silently does nothing. No exception, no failed schema check: the JSON was valid, the anchor was a plausible string, the apply step simply matched zero occurrences. In a batch of twelve proposed redlines, three quietly don't apply and the document looks reviewed.

Worse is the near-miss that does match — an anchor the model paraphrased into something that happens to exist elsewhere in the document, so the edit lands in the wrong clause.

Rule 1 — verify the quote against the source, locally

Every anchor and quote the model claims to have copied is checked to appear verbatim in the original, modulo whitespace and smart punctuation.

Those two tolerances are necessary, not sloppy: documents arrive with curly quotes, non-breaking spaces and soft line-wraps that no model reproduces byte-for-byte, and rejecting on those alone fails every real document. Anything beyond that is treated as not-found.

This runs locally. No second model call to "check" the first — that costs money, adds latency, and asks the same class of system to audit itself.

Rule 2 — coerce what is safely coercible, reject the rest

Models wrap JSON in prose, in markdown fences, in fences tagged as the wrong language, and occasionally emit legacy field values. All of that is recoverable and is recovered.

null is returned only on a real parse failure. The distinction matters: a caller that cannot tell "the model wrote prose around valid JSON" from "the model produced nothing usable" will either throw away good output or ship broken output, and both look like the model being flaky.

Rule 3 — one authoritative definition of the shapes

Redline and summarize both ask a model for JSON, and both are parsed here. The types are shared deliberately, so a field renamed in one flow cannot silently diverge from the other — a drift that surfaces as one panel rendering blank while the other works.

What this does NOT do

No model calls, no prompting, no .docx reading or writing, no applying of edits. It defines the contract and verifies the reply against your source text. You bring the model and the applier.

It cannot tell you whether a correctly quoted edit is a good edit. It checks provenance, not judgement.

Verified

33 tests covering fenced and prose-wrapped JSON, wrong fence tags, legacy field coercion, whitespace and smart-punctuation tolerance, anchors that do not appear in the source, and the parse failures that must return null.

01Capabilities

Does

  • + LLM output parsing
  • + Document text integrity
  • + Schema contract enforcement

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

Nobody has reported anything yet — a success counts as a report too.

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 7 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
0.1.0stableAug 11, 2026Initial extraction.